Vulnerability record · CVE-2008-4696 · published 23 October 2008
CVE-2008-4696: Opera stored XSS via unescaped anchor identifier in History Search
Opera · Opera
Opera before 9.61 fails to escape the anchor identifier (the optional fragment) before storing it in the History Search database (md.dat). A remote attacker can inject arbitrary web script or HTML that is later rendered from stored history data. This is a stored cross-site scripting flaw in the browser itself, affecting all users of the vulnerable version.
Description
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML via the anchor identifier (aka the "optional fragment"), which is not properly escaped before storage in the History Search database (aka md.dat).
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
medium priorityCVSS 2.0 score is 4.3 (MEDIUM) with only partial integrity impact, but public exploit code and high EPSS percentile raise the practical risk.
What it is
Opera before 9.61 fails to escape the anchor identifier (the optional fragment) before storing it in the History Search database (md.dat). A remote attacker can inject arbitrary web script or HTML that is later rendered from stored history data. This is a stored cross-site scripting flaw in the browser itself, affecting all users of the vulnerable version.
Impact
An attacker can execute arbitrary script or HTML in the context of the victim's browser session, potentially stealing data or performing actions as the user. The CVSS vector shows partial integrity impact only, with no confidentiality or availability impact.
Attack surface
Reached remotely over the network (AV:N) with medium complexity (AC:M) and no authentication required (Au:N). The description does not state whether user interaction is needed, but the vector and stored nature imply the victim must visit a crafted page or link for the payload to be stored and later rendered.
Exploitation
Not listed in CISA KEV. EPSS 30-day probability is 0.45729 (98.7th percentile), indicating high predicted activity. Reference tags include Exploit and Patch, and an Exploit-DB entry exists, so public exploit code is available.
What to do
- Upgrade Opera to version 9.61 or later, which contains the fix.
- Apply vendor patches from the Opera 9.61 changelogs for all affected platforms.
- If upgrade is not possible, restrict use of the vulnerable Opera version for untrusted web browsing.
- Clear or disable the History Search database (md.dat) where feasible to remove stored payloads.
Detection
- Monitor for Opera versions below 9.61 in asset inventories and flag them for upgrade.
- Inspect md.dat or History Search data for unexpected script or HTML content in anchor identifiers.
- Review web proxy or browser logs for requests containing suspicious fragment identifiers targeting Opera users.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-4696 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-4696), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.